
Discovery, mapping, and inventory of your IT assets
You cannot protect what you do not know. Comprehensive and continuous mapping of your IT infrastructure is the foundation of any cybersecurity strategy. Cyberwatch automatically discovers and inventories all your assets: endpoints, cloud, OT, external surface, and software libraries.
Shadow IT: the blind spot in your security
Most organizations only know a fraction of their IT assets. Forgotten servers, orphaned VMs, unlisted cloud instances, undocumented network equipment, exposed subdomains, and uninventoried software dependencies: this shadow IT represents an invisible and unprotected attack surface.
Without a comprehensive and up-to-date inventory, your vulnerability scans only cover a fraction of your actual exposure. Attackers, however, target exactly what you cannot see.

Shadow IT / OT

Unlisted devices connected to the network without oversight act as invisible entry points for attackers.
Outdated manual inventories

Excel files and self-reported inventories never reflect the reality on the ground. The gaps only widen with every maintenance intervention.
Strict regulations

NIS2, LPM, IEC 62443: regulations require an up-to-date inventory of critical industrial assets, complete with traceability and audit trails.
Discovery
Automated multi-perimeter discovery
Internal infrastructure
Network scans (IP ranges, reverse DNS), Active Directory integration, hypervisor connectors (VMware, Proxmox, Hyper-V, etc.). Discovery of servers, workstations, VMs, and network equipment.
Cloud and containers
API connection to cloud providers (AWS, Azure, Google Cloud, OpenStack). Automatic inventory of instances, VMs, containers, Kubernetes clusters, and image registries.
External surface
DNS enumeration, WHOIS, Certificate Transparency, and public IP scanning. Discovery of subdomains, exposed services, and unreferenced assets accessible from the Internet.
OT / Industrial systems
Native Rockwell, Schneider, and Siemens connectors. SNMP, Modbus, and S7-Comm protocols. Non-intrusive inventory of PLCs and industrial equipment.
Software libraries
SCA (Software Composition Analysis) for npm, yarn, Maven, Composer, pip, NuGet, RubyGems, and Go. Open-source component inventory and SBOM generation (CycloneDX, SPDX).
Identities and directories
Active Directory, Entra ID, Microsoft 365. Inventory of accounts, groups, delegations, GPOs, and critical permissions across your organization.
inventory
A dynamic, context-aware inventory
Continuous updates
The inventory updates with every scan. Assets that appear, disappear, or are modified are detected automatically.
- Rockwell Automation— ControlLogix, CompactLogix, MicroLogix (via EtherNet/IP)
- Schneider Electric— Modicon M340, M580, Premium, Quantum (via Modbus TCP)
- Siemens— SIMATIC S7-300, S7-400, S7-1200, S7-1500 (via S7 protocol)
Business context
Organize your assets into projects and groups aligned with your priorities: production, DMZ, development, OT. Assign a CIA (Confidentiality, Integrity, Availability) criticality level to each perimeter.
- Managed switches, routers, and industrial firewalls (Cisco, Hirschmann, Moxa, Fortinet, etc.)
- SNMP v1/v2c/v3 polling for inventory and firmware vulnerability detection
Over 50 connectors
Cyberwatch interfaces with your existing tools: Active Directory, VMware, AWS, Azure, GCP, CMDB, Jira, ServiceNow, GLPI.
- SCADA / DCS servers, HMI supervision stations
- Windows and Linux operator workstations in industrial networks
- OS and application vulnerability scanning with or without an agent, including on legacy Windows systems (Server 2008, 2012)
Dynamic groups
Create automatic filtered views by OS, location, criticality, or any other attribute. Restrict access by team.
- SCADA / DCS servers, HMI supervision stations
- Windows and Linux operator workstations in industrial networks
- OS and application vulnerability scanning with or without an agent, including on legacy Windows systems (Server 2008, 2012)

Nozomi Networks
Inventory import from Nozomi probes already deployed on your industrial networks
- Item 1
- Item 2
- Item 3
Allentis (Framatome subsidiary)
Native connector with Allentis NDR probes, ANSSI-qualified, for unified IT/OT mapping
- Item 1
- Item 2
- Item 3
Seckiot
Integration with Seckiot sensors to enrich the OT inventory
- Item 1
- Item 2
- Item 3
Seckiot
Correlation between network data (probes) and system data (Safe Query) for a complete and deduplicated inventory
- Item 1
- Item 2
- Item 3
Mapping is the foundation of all vulnerability management—it determines the effectiveness of detection, prioritization, and remediation.
reporting and API
Reporting and integrations
Cyberwatch is designed to fit into your ecosystem: export your data to your ITSM tools, feed your dashboards, connect your AI models, or industrialize your exports. Four complementary channels cover all use cases.
PDF Reports
Automatically generated executive and technical reports: overall security posture, top vulnerabilities, SLA tracking, and regulatory compliance. Customizable templates branded to your organization and scheduled exports.
API and Exports
Documented API for automating exports, CMDB integrations, and bidirectional synchronization with ServiceNow, GLPI, and Jira. CSV/JSON exports of inventory and vulnerabilities, with ready-to-use cURL and PowerShell snippets.
Dashboards and analytics
Build your dashboards directly within the software, without the need for third-party tools: indexes are documented and accessible. For advanced analysis, data can be exported to your own analytics environment or security data lake.
MCP Server
Connect Cyberwatch to any language model (Claude, GPT, Mistral, Llama, etc.) via the Model Context Protocol. Query your inventory in natural language, generate summaries, and automate your security workflows.
Testimonials
FAQ
From asset mapping to automated remediation.
How does Cyberwatch automatically discover IT assets?
Cyberwatch combines several methods: network scanning and subdomain discovery to detect Shadow IT, direct queries to cloud APIs (AWS, Azure, Google Cloud), connections to existing infrastructure tools (Active Directory, LDAP, CMDB, VMware, network equipment, etc.), and native connectors for OT environments. These discovery processes run continuously, without manual intervention, to ensure your inventory is always up to date.
Does the IT asset mapping include open-source software libraries?
Yes, Cyberwatch integrates SCA (Software Composition Analysis) to inventory the open-source components used in your development projects, including those on npm, Maven, pip, NuGet, or Go. This software inventory is complemented by the automatic generation of a Software Bill of Materials (SBOM), which is essential for regulatory compliance and the traceability of your software supply chain.
Can Cyberwatch map industrial (OT) environments?
Yes, Cyberwatch features native connectors for Rockwell, Schneider, and Siemens PLCs via SNMP, Modbus, and S7-Comm protocols. Industrial equipment inventory is performed non-intrusively, an essential requirement in OT environments where overly aggressive scanning can disrupt critical physical processes.
Why is an inventory of identities and directories part of IT mapping?
Identities (accounts, groups, permissions) represent an attack surface in their own right, one that is often overlooked in traditional mapping processes. Cyberwatch inventories Active Directory, Entra ID, and Microsoft 365 directories, including delegations and GPOs, to reveal poorly managed critical permissions that could lead to privilege escalation.
How can I use Cyberwatch inventory data in my existing tools?
Cyberwatch offers four export channels: executive and technical PDF reports, a REST API to sync with your CMDBs (ServiceNow, GLPI, Jira), Elasticsearch/Kibana access for advanced dashboards, and an MCP server that lets you query your inventory in natural language using AIs like Claude, ChatGPT, or Mistral.
